ServiceNow’s patched CVE-2026-6875 remote code execution flaw in its AI platform is reportedly being exploited in the wild, with evidence linked to technical details released by Searchlight Cyber. ServiceNow says it has not seen signs of abuse on hosted instances and is urging both hosted and self-hosted customers to apply the available fixes. #CVE-2026-6875 #ServiceNow #SearchlightCyber #Defused
Keypoints
- CVE-2026-6875 is a critical sandbox escape vulnerability in ServiceNow AI.
- The flaw may allow an unauthenticated attacker to execute arbitrary code.
- ServiceNow deployed patches to hosted instances on July 14.
- Self-hosted customers must manually install the security updates.
- Defused reported in-the-wild exploitation using details published by Searchlight Cyber.
Read More: https://www.securityweek.com/exploitation-of-servicenow-vulnerability-seen-days-after-disclosure/